CVE-2025-8662: Input Validation
Published Sep 2, 2025
·Updated
OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: from 14.0.0 through 14.0.1.
Affected Software
2 affected components
OpenAM OpenAM>=14.0.0<=14.0.1
OpenAM OpenAM>=14.0.0<14.0.2
Remediation
Information
The OpenAM Consortium has released OpenAM 14.0.2, which addresses the vulnerability.
Please update to the released OpenAM version.
Event History
Sep 2, 2025
CVE Published
via MITRE·02:06 AM
Data Sourced
via MITRE·02:06 AM
RemedyDescription
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Nov 20, 57657
Event
via FIRST·07:37 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-8662?
CVE-2025-8662 has a critical severity as it can undermine the security of SAML authentication in OpenAM.
2
How do I fix CVE-2025-8662?
To fix CVE-2025-8662, upgrade OpenAM from version 14.0.0 to a later version beyond 14.0.1.
3
What software versions are affected by CVE-2025-8662?
CVE-2025-8662 affects OpenAM versions 14.0.0 through 14.0.1.
4
What type of vulnerability is CVE-2025-8662?
CVE-2025-8662 is a vulnerability related to tampered requests that can affect functionality as a SAML IdP.
5
Can CVE-2025-8662 be exploited remotely?
Yes, CVE-2025-8662 can potentially be exploited remotely by attackers manipulating SAML requests.